<Vulnerability name="CVE-2026-76037">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-18T20:31:25</PublicDate>
    <Bugzilla id="2518261" url="https://bugzilla.redhat.com/show_bug.cgi?id=2518261" xml:lang="en:us">
chromium-browser: Google Chrome: Arbitrary Code Execution via Link Following
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>8.2</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-59</CWE>
    <Details xml:lang="en:us" source="Mitre">
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Google Chrome. A local attacker could exploit a link following vulnerability within the CredentialProvider component. This vulnerability allows for the execution of arbitrary code outside the browser's security sandbox through a local program.
    </Details>
    <Statement xml:lang="en:us">
This vulnerability affects Chromium-based browsers and applications utilizing QtWebEngine in Red Hat Community Projects. A local attacker could exploit a link following flaw within the CredentialProvider component, leading to arbitrary code execution outside the browser's sandbox. Exploitation requires user interaction, such as clicking a malicious link.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-76037
https://nvd.nist.gov/vuln/detail/CVE-2026-76037
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0826575033.html
https://issues.chromium.org/issues/517612295
    </References>
</Vulnerability>